Courseiva

GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts

An analyst is examining a memory capture to identify malicious code injection. Which volatility plugin would best help determine if a process has been hollowed by inspecting the base address and the VAD (Virtual Address Descriptor) properties of the memory segments?

⚠ Common exam trap

Examinees often confuse basic process enumeration plugins with memory injection detectors, failing to utilize specialized tools that evaluate VAD permissions and unbacked memory regions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

malfind

The malfind plugin is the standard tool for identifying injected code by scanning for memory segments with Execute/Read/Write permissions that are not backed by a file on disk. This is a critical step in volatile memory analysis because malware often uses process hollowing to hide its execution flow within legitimate system processes. Comparing VAD protections helps confirm the anomaly, which is a hallmark of sophisticated persistent threats evading standard file-based detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    pslist

    Why it's wrong here

    Pslist only enumerates processes based on the EPROCESS block structure in memory. It provides a snapshot of running processes and parent-child relationships but does not inspect the internal memory protections or VAD structures of those processes. Therefore, it lacks the capability to detect code injection or hollowed memory segments.

  • ✗

    handles

    Why it's wrong here

    The handles plugin displays open handles for a process, such as files, registry keys, or mutexes. While useful for identifying indicators of compromise like malicious mutexes or file locks, it does not analyze the memory segments or VAD flags that are essential for detecting process hollowing or injected code.

  • ✓

    malfind

    Why this is correct

    Malfind specifically scans for VAD nodes marked as PAGE_EXECUTE_READWRITE that lack an associated mapped file. This is the primary signature of injected code or hollowed processes where attackers have manually allocated memory to house malicious payloads. It provides the necessary visibility into anomalous memory protections within target processes.

  • ✗

    pstree

    Why it's wrong here

    Pstree provides a hierarchical view of the process tree, showing parent and child relationships. While it is excellent for identifying process lineage anomalies, such as a web server spawning a command shell, it does not perform deep inspection of the memory address space or VAD flags for injected code.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.